MALICIOUS — Aurora15Connector.exe
MALICIOUS — Aurora15Connector.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Lazy family. 8 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
1b342b016b047449460e4e20239be1242c65c8067d36e5a44572ba523ff417cb - SHA-1:
1c81ef4bd1a6fda31dd02e4ca13a5b6ab3e92e60 - MD5:
f429403f3656caa49bedd699a36d0dff - imphash:
027eac1382f09c1377726a7aad4defc6 - ssdeep:
98304:BloWOzOZTIQPsK6a7fsPSiLxiOFvKrGNIR:XoWrZTtsKV7fWBbF/I - TLSH:
T1E76B8CAA062F5173F1FBED847C1CDADD89A1B09A54339B5C45039E2DC8D1037ADE12A8 - Submitted as: Aurora15Connector.exe
- File type: pe · Size: 10111488 bytes
- Verdict: malicious (100/100) · Family: Lazy
Detections (8 of 56 engines)
- capa (capabilities): capability:execution/powershell
- ClamAV (daily): Win.Malware.Lazy-10060471-0
- YARA: bartblaze: BB_Clipbanker
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Stratosphere IPS: STRATO_Tor_Onion_C2
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Emsisoft (Emergency Kit): Gen:Variant.Mikey.194335
- Kaspersky (KVRT): UDS:DangerousObject.Multi.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Malware.Lazy-10060471-0 (rule
Win.Malware.Lazy-10060471-0) - engine signal, weight 0.90, confidence 0.95 - YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.70, confidence 0.70 - Emsisoft (Emergency Kit) flagged Gen:Variant.Mikey.194335 (rule
Gen:Variant.Mikey.194335) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged UDS:DangerousObject.Multi.Generic (rule
UDS:DangerousObject.Multi.Generic) - engine signal, weight 0.55, confidence 0.85 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.60, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_Tor_Onion_C2 (rule
STRATO_Tor_Onion_C2) - engine signal, weight 0.50, confidence 0.70 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://ea.com/license, http://127.0.0.1, http://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.apache.org/licenses/
- http://www.apache.org/licenses/LICENSE-2.0
- http://ea.com/license
- http://www.w3.org/1999/xhtml
- http://schemas.microsoft.com/win/2004/08/events/event
- https://aka.ms/GlobalizationInvariantMode
- https://go.microsoft.com/fwlink/?linkid=2233907
- http://127.0.0.1
- http://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- http://schemas.microsoft.com/ws/2008/06/identity/claims/denyonlyprimarysi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/groupsi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/primarysi
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsdeviceclai
- http://schemas.microsoft.com/ws/2008/06/identity/claims/windowssubauthorit
- http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysi
- http://www.w3.org/2000/xmlns
- http://www.w3.org/2001/XMLSchema#boolea
- http://www.w3.org/2001/XMLSchema#strin
- http://www.w3.org/2003/11/xpath-datatype
- https://aurora15.onlyonemzy.com
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/client.zi
- https://aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.8/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://cdn.aurora15.onlyonemzy.com.example.invalid/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/releases
- https://cdn.aurora15.onlyonemzy.com/fifa15/connect/releases/1.0.7/0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF/Aurora15Connector.ex
Embedded domains
- github.com
- www.apache.org
- fesl.ea.com
- spring14.gosredirector.ea.com
- ea.com
- www.w3.org
- schemas.microsoft.com
- aurora15.onlyonemzy.com
- go.microsoft.com
- discord.gg
- game.aurora15.onlyonemzy.co
- schemas.xmlsoap.org
- cdn.aurora15.onlyonemzy.com
- missing-adjacent.in
- saved.in
- aka.ms
- cdn.aurora15.onlyonemzy.com.example.invalid
Embedded IP addresses
- 1.1.50.0
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 1.12.10.1
- 1.9.16.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 151.242.127.14
- 1.101.2.1
- 1.101.3.4
- 203.0.113.1
- 1.1.48.0
File paths
- C:\Users\Natha\Documents\Playground\Aurora15\tools\EA-MITM\out\EA-MITM_x64_Release.pdb
- Z:\Program
- C:\FIFA
- C:\Other
- C:\Games\FIFA
- C:\Program
More Lazy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report